Re: DMARC, not DKIM
DMARC is massively broken, because it mandates an SPF test on the From header, even if a Sender header is present. What it should do is to test the Sender if present, else the From, but it doesn't.
Most mailing lists work completely RFC-compliant by adding a Sender header (known as the 'secretary scenario'). However, to get past DMARC tests, they have to violate the RFC and rewrite the From header instead, concealing the originator of the mail.